CVE-2026-92457 UNKNOWN

CVE-2026-92457

Published: 2026-09-16

Description

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status, inflate contract invoiced amounts with attacker-chosen values, and trigger invoice emails to arbitrary addresses.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…